news4geeks.net
17Apr/120

New Mac malware exploits old Java hole


one of 14 downloads is malwareSecurity specialist Sophos reports that it has discovered new Mac malware which exploits the same Java hole in Mac OS X that was also used by the "Flashback" malware and has since been closed by Apple. The backdoor trojan is called "OSX/Sabpab-A" and is said to establish a HTTP connection to a command & control server once it has infected a computer. According to Sophos's Graham Cluley, attackers then have the ability to execute arbitrary commands, upload and download files, and take screenshots on infected systems.

The security firm says that, like Flashback, OSX/Sabpab-A spreads via the web; apparently, simply visiting a malicious web page on a Mac with an unpatched version of Java is all that's required to become infected. Sophos provides no further details on the distribution of the malware but has given it a low "prevalence" rating.

Users can protect their systems by installing the latest Java updates, which fixes the problem and automatically disables the Java web plugin by default; users can re-enable this via the Java Preferences application (Applications ➤ Utilities ➤ Java Preferences).

(Source: h-online.com)

 

Opera 11.64 closes critical code execution hole
Version 11.64 of the Opera web browser has been released, closing a critical hole that could have been exploited by attackers to inject malicious code into a ...
READ MORE
Flashback numbers not going down – still over half a million
Dr Web's estimate of Flashback infections Source: Dr Web Initial reports of drops in the number of systems infected with the Flashback Mac malware are being ...
READ MORE
New Mac malware exploits Java bugs, steals passwords
A new version of a well-known family of Mac malware exploits vulnerabilities in Java to steal usernames and passwords for online payment, banking, and credit card websites. Flashback.G is ...
READ MORE
Opera 11.64 closes critical code execution hole
Flashback numbers not going down – still over
New Mac malware exploits Java bugs, steals passwords

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.